Home
CRITICAL: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDefault status
unaffected
0.0.0 (semver) before 1.7.3
affected
Default status
unaffected
0.0.0 (semver) before 1.7.3
affected
Default status
unaffected
0.0.0 (semver) before 1.7.3
affected
Default status
unaffected
0.0.0 (semver) before 1.7.3
affected
Description
An unauthenticated remote attacker can alter the device configuration in a way to get remote code execution as root with specific configurations.
Problem types
CWE-913 Improper Control of Dynamically-Managed Code Resources
Product status
0.0.0 (semver) before 1.7.3
0.0.0 (semver) before 1.7.3
0.0.0 (semver) before 1.7.3
0.0.0 (semver) before 1.7.3
Credits
Tobias Scharnowski
Felix Buchmann
Kristian Covic
References
certvde.com/de/advisories/VDE-2025-019